Hi malware fighhters,
While visiting this site: hxtp://topdocumentaryfilms.com/arrivals/ and watching the video part 1 in Firefox - firekeeper alerted this:
================ FIREKEEPER LOG ENTRY ================
2010.2.4 21:17:35 Alert htXp://v8.lscache1.c.youtube.com/videoplayback?ip=0.0.0.0&sparams=id%2Cexpire%2Cip%2Cipbits%2Citag%2Calgorithm%2Cburst%2Cfactor&algorithm=throttle-factor&itag=34&ipbits=0&burst=40&sver=3&expire=1267758000&key=yt1&signature=8C1161EAE94142F6D989E3E6559C2F0B98A5CBD0.512D9F9B44B915396860B18C379D0301EFE710D6&factor=1.25&id=2bcdb1d70a4dcb2b; winamp .cda file name overflow attempt
DETAILS:
=== Triggered rule ===
alert (msg:"winamp .cda file name overflow attempt"; body_content
My question is could this probably be malicious behavior?
I blocked the behavior through Firekeeper extension in Firefox,
polonus